Zloader With a New Infection Technique
ID: 34509347-4d29-5a75-a4b1-2a927dde530d
STIX ID: report--34509347-4d29-5a75-a4b1-2a927dde530d
Feed Name: McAfee Labs Blog
This McAfee Labs analysis details a Zloader infection chain: phishing emails deliver a malicious Word document which downloads a password-protected Excel file; the Word VBA reads cell contents and writes macros into the Excel file, modifies registry settings to disable Excel macro warnings, and triggers an Auto_Open macro that downloads a Zloader DLL (.cpl) and executes it via rundll32. The report includes IOCs (SHA-256 hashes and download URLs), detection signatures, mitigation advice, and mappings to relevant MITRE ATT&CK techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
